From: sashiko-bot@kernel.org
To: "Leon Hwang" <leon.hwang@linux.dev>
Cc: bpf@vger.kernel.org
Subject: Re: [PATCH bpf-next 05/13] libbpf: Add tracing_multi link support for bpf progs
Date: Sun, 09 Aug 2026 15:21:37 +0000 [thread overview]
Message-ID: <20260809152138.45FA81F000E9@smtp.kernel.org> (raw)
In-Reply-To: <20260809150111.45000-6-leon.hwang@linux.dev>
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [Medium] Missing input validation in `bpf_program__attach_tracing_multi` leads to a potential segmentation fault when a user-provided array element is NULL.
--
--- Patch [5]: [PATCH bpf-next 05/13] libbpf: Add tracing_multi link support for bpf progs ---
commit bef5c103ea1916738efc32c272265795c04de90a
Author: Leon Hwang <leon.hwang@linux.dev>
libbpf: Add tracing_multi link support for bpf progs
This commit introduces tracing_multi link support for bpf programs in libbpf.
It adds fds and funcs fields to bpf_tracing_multi_opts to specify target
programs, translating the function names to BTF IDs before passing them to
the kernel.
> diff --git a/tools/lib/bpf/libbpf.c b/tools/lib/bpf/libbpf.c
> index 514e4e9daa825..d698a64ff8002 100644
> --- a/tools/lib/bpf/libbpf.c
> +++ b/tools/lib/bpf/libbpf.c
[ ... ]
> @@ -12720,11 +12732,28 @@ bpf_program__attach_tracing_multi(const struct bpf_program *prog, const char *pa
> if (cnt == 0)
> return libbpf_err_ptr(-EINVAL);
> ids = (const __u32 *) free_ids;
> + } else if (fds) {
> + size_t cap = 0;
> + int i;
> +
> + err = libbpf_ensure_mem((void **) &free_ids, &cap, sizeof(*free_ids), cnt);
> + if (err)
> + return libbpf_err_ptr(err);
> +
> + for (i = 0; i < cnt; i++) {
> + err = libbpf_find_prog_btf_id(funcs[i], fds[i], prog->obj->token_fd);
[Severity: Medium]
Could funcs[i] be NULL here if the user-space application provided an invalid
string pointer in the array?
If it is NULL, this pointer gets passed down through libbpf_find_prog_btf_id()
and eventually reaches btf_find_by_name_kind(), which performs this check:
tools/lib/bpf/btf.c:btf_find_by_name_kind() {
...
if (kind == BTF_KIND_UNKN || strcmp(type_name, "void") == 0)
...
}
Calling strcmp() with a NULL type_name will cause a segmentation fault in
the application. Is it worth validating that funcs[i] is not NULL to safely
return an error code instead of crashing?
> + if (err < 0)
> + goto error;
> +
> + free_ids[i] = err;
> + }
> + ids = (const __u32 *) free_ids;
> }
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260809150111.45000-1-leon.hwang@linux.dev?part=5
next prev parent reply other threads:[~2026-08-09 15:21 UTC|newest]
Thread overview: 25+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-09 15:00 [PATCH bpf-next 00/13] bpf: Add tracing_multi link support for bpf progs Leon Hwang
2026-08-09 15:00 ` [PATCH bpf-next 01/13] bpf: Initialize ftrace_managed in bpf_trampoline_get Leon Hwang
2026-08-09 15:01 ` [PATCH bpf-next 02/13] bpf: Factor out update_fentry_multi helper Leon Hwang
2026-08-09 15:14 ` sashiko-bot
2026-08-09 15:01 ` [PATCH bpf-next 03/13] bpf: Drop unnecessary ftrace_location() in update_fentry_multi() Leon Hwang
2026-08-09 15:01 ` [PATCH bpf-next 04/13] bpf: Add tracing_multi link support for bpf progs Leon Hwang
2026-08-09 15:33 ` sashiko-bot
2026-08-10 13:13 ` Jiri Olsa
2026-08-11 6:12 ` Leon Hwang
2026-08-09 15:01 ` [PATCH bpf-next 05/13] libbpf: " Leon Hwang
2026-08-09 15:21 ` sashiko-bot [this message]
2026-08-09 15:01 ` [PATCH bpf-next 06/13] bpf: Add tracing_multi link fdinfo " Leon Hwang
2026-08-09 16:20 ` bot+bpf-ci
2026-08-09 15:01 ` [PATCH bpf-next 07/13] bpf: Add tracing_multi link info " Leon Hwang
2026-08-09 15:17 ` sashiko-bot
2026-08-09 15:01 ` [PATCH bpf-next 08/13] selftests/bpf: Add tracing_multi bpf prog attach test Leon Hwang
2026-08-09 15:01 ` [PATCH bpf-next 09/13] selftests/bpf: Add tracing_multi bpf prog attach failure tests Leon Hwang
2026-08-09 15:17 ` sashiko-bot
2026-08-09 15:01 ` [PATCH bpf-next 10/13] selftests/bpf: Add tracing_multi bpf prog cookie test Leon Hwang
2026-08-09 16:20 ` bot+bpf-ci
2026-08-09 15:01 ` [PATCH bpf-next 11/13] selftests/bpf: Add tracing_multi bpf prog rollback test Leon Hwang
2026-08-09 15:21 ` sashiko-bot
2026-08-09 15:01 ` [PATCH bpf-next 12/13] selftests/bpf: Add tracing_multi bpf prog link info test Leon Hwang
2026-08-09 15:29 ` sashiko-bot
2026-08-09 15:01 ` [PATCH bpf-next 13/13] selftests/bpf: Test tailcall with fentry.multi Leon Hwang
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260809152138.45FA81F000E9@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=bpf@vger.kernel.org \
--cc=leon.hwang@linux.dev \
--cc=sashiko-reviews@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.